2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-62104CRITICAL10Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
CVE-2026-62101CRITICAL9.8Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
CVE-2026-92860CRITICAL9.1A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fm...
CVE-2026-90823CRITICAL9.8FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based b...
CVE-2026-90822CRITICAL9.8FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command i...
CVE-2026-15688CRITICAL9.2Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control S...
CVE-2026-88795CRITICAL9The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, ...
CVE-2026-86710CRITICAL9.8The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, m...
CVE-2026-86709CRITICAL9.8The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication ...
CVE-2026-86707CRITICAL9.8The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is on...
CVE-2026-87796CRITICAL9.8The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, ...
CVE-2026-61594CRITICAL9.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-92805CRITICAL9.8UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Conf...
CVE-2026-92787CRITICAL9.8Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypas...
CVE-2026-76460CRITICAL10A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to byp...
CVE-2026-75513CRITICAL9.1Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marte...
CVE-2026-20332CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl...
CVE-2026-20284CRITICAL9.1A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection ...
CVE-2026-92808CRITICAL10A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An un...
CVE-2026-89083CRITICAL9.3HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, ...
CVE-2026-89082CRITICAL9.3HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, ...
CVE-2026-88592CRITICAL9.1kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFi...
CVE-2026-76423CRITICAL10A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain a...
CVE-2026-20341CRITICAL9.1A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenti...
CVE-2026-20330CRITICAL9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now